A.5.20 Addressing information security within supplier agreements
Establish and agree the relevant security requirements in each supplier contract.
20
artefacts
2
held by a system
5
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Communication log with supplier on incidents · SIEM / log platform
- Service level agreement security metrics report · SIEM / log platform
periodic reviewEvidence produced at each review
- Signed supplier contract with security annex · Vendor register / contract repository
- Risk assessment report for supplier · Vendor register / contract repository
- Record of security incident notifications from supplier · Vendor register / contract repository
- Monthly compliance dashboard · SIEM / log platform
- Record of data sanitization verification after termination · HR system / LMS
governing documentDocuments that govern the control
- Security requirements addendum · Vendor register / contract repository
- Confidentiality and data protection clause · Vendor register / contract repository
- Access control obligations schedule · Policy repository / GRC workspace
- Supplier due diligence questionnaire · Vendor register / contract repository
- Risk rating matrix · Vendor register / contract repository
- Approval memo from risk owner · Vendor register / contract repository
- Incident response clause in contract · Vendor register / contract repository
- Incident handling workflow document · Document repository
- Audit findings report on supplier · Policy repository / GRC workspace
- Penalty notice for security breach · Policy repository / GRC workspace
- Termination clause with data return and destruction requirements · HR system / LMS
- Exit checklist for supplier · HR system / LMS
- Certificate of data destruction · HR system / LMS
First move
Mostly documents and reviews. Pull the 2 system-held artefacts from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- missing explicit security clauses
- no documented risk assessment before onboarding
- lack of ongoing monitoring evidence
- inadequate incident reporting procedures
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.5.19 Information security in supplier relationships · A.5.21 Managing information security in the ICT supply chain